Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=uat.platform.osp-activation.idosoft.dev
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 23, 2025
Valid Until
February 21, 2026
85 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
37:77:B4:A9:5D:91:C9:81:EE:6E:01:8D:33:27:0C:12:20:91:B3:AA:3E:0F:80:C5:FB:90:80:5D:9E:16:DE:DF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
casapreta.com.br
dashboard.acroworld.de
aerothread.net
otomasyon.alperakar.com
www.anime.world
contents-manager.anomalith-systems.com
aluno.kettu.app.br
appho.st
arpartners.io
bau-spille.de
internal-ux.bolste.net
borderwatcher.hu
www.brickwise.uk
reflect.burson.family
cedarpumps.com
app.colombiaenmoto.com
sontorino.com.vn
www.derive.me
www.equal-line.com
www.esnetworks.com
balloon.factorem.co
adel-progressus.farmacare.dev
www.firstwealth.co
app.development.flouria.health
futuralabs.mx
www.graciuscocoa.com
www.ha4gu.com
pf.hamajima.co.jp
precheck-backoffice.dev.heycharge.com
www.hinged.nl
biodata.hrushi.pro
filtercodex.cupoftea.id.vn
uat.platform.osp-activation.idosoft.dev
intemlabs.com
www.intemlabs.com
www.inventsoftlabs.in
www.phuongthaogaming.io.vn
www.ipic-asso.fr
dt-live.jawsapp.online
docs.kfz.app
kinet.store
kontaktlinsen-preisvergleich.de
lbh-portable.com
lullaby200.com
applinks.luluhypermarket.com
www.matt.is
www.mealuga.com
staging.humantold.medcon.live
globe.memo.ph
mesbro-ads.mesbro.in
www.miguelvesco.ca
fairwayglobal.room.monetix.io
tienda.develop.website.moons.ninja
motapi.com
scene.mr-cheesecake.com
munfai.com
sdnegeri1.sidaraja.my.id
www.myspecialexperience.com
nael.org
spot.niologic.com
www.nudeart.photography
app.opennaukri.com
admin.orgramicfarms.com
own-english-word.com
pawgotyou.com
ergo-cms-staging.peaksandpies.io
be.perapera.ai
persovid.com
pixelartify.com
practical.prasetya.id
primemotion-supplies.ca
www.primemotion-supplies.ca
qacampus.qaware.de
questopconsulting.com
r4f4siqueira.com
raalfeengenharia.com.br
www.rezappt.ch
bulb.rouic.com
rubipasteleria.com
sagasofyore.com
shoemaker-bees.com
moladibari.smartpol.it
forum.solidsail.com
my.sourceview.co
www.spacematch.me
spacexdata.info
business.sportshi.io
admin.staypick.kr
www.survivorstudents.com
www.sylaratomic.com
tallyflex.com
www.taxichiclana9plazas.com
techhillcompany.ng
truleaf.in
unagi.mojo.una.events
necessito.webcoop.cat
webmd.labs.accord.ninefunds.websheet.io
kyobo-admin.withreaders.com
woliegtdas.de
yaki.company
Other domains in certificate